What would you like?
It appears that kit/transport/grpc is vulnerable to the attack outlined in CVE-2022-41717 due to the package dependency on the Go gRPC implementation. Can go-kit be updated to leverage fixes for this vulnerability? It is fixed in Go minor releases 1.18.9 and 1.19.4.